Attachmate Reflection X ActiveX Control 'ControlID' Buffer Overflow Vulnerability
BID:40243
Info
Attachmate Reflection X ActiveX Control 'ControlID' Buffer Overflow Vulnerability
| Bugtraq ID: | 40243 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 18 2010 12:00AM |
| Updated: | Jun 04 2010 07:30PM |
| Credit: | Rad L. Sneak |
| Vulnerable: |
Attachmate Reflection X 14.0.5 Attachmate Reflection X 14.0 Attachmate Reflection X 13.0 Attachmate Reflection Standard Suite 2008 0 Attachmate Reflection for UNIX and OpenVMS 14.0.5 Attachmate Reflection for IBM 14.0.5 Attachmate Reflection for IBM 14 Attachmate Reflection for HP 14.0.5 Attachmate Reflection 13.0.5 Attachmate Reflection 13.0.4 Attachmate Reflection 14.0 SP1 Attachmate Reflection 14.0 Attachmate Reflection 13.0 |
| Not Vulnerable: |
Attachmate Reflection X 14.1 Attachmate Reflection 14.1 |
Discussion
Attachmate Reflection X ActiveX Control 'ControlID' Buffer Overflow Vulnerability
Attachmate Reflection X ActiveX control is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
Successful exploits may allow an attacker to execute arbitrary code in the context of a user running the affected application. Failed attempts will likely result in denial-of-service conditions.
The following are vulnerable:
Attachmate Reflection X 13.0 and 14.0
Attachmate Reflection Standard Suite 2008
Attachmate Reflection X ActiveX control is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
Successful exploits may allow an attacker to execute arbitrary code in the context of a user running the affected application. Failed attempts will likely result in denial-of-service conditions.
The following are vulnerable:
Attachmate Reflection X 13.0 and 14.0
Attachmate Reflection Standard Suite 2008
Exploit / POC
Attachmate Reflection X ActiveX Control 'ControlID' Buffer Overflow Vulnerability
The following proofs of concept are available:
The following proofs of concept are available:
Solution / Fix
Attachmate Reflection X ActiveX Control 'ControlID' Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Attachmate Reflection X ActiveX Control 'ControlID' Buffer Overflow Vulnerability
References:
References:
- Attachmate Homepage (Attachmate)
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Technical Note 1708 Security Updates and Reflection (Attachmate)